Hello team!!
We have 2 Fortigates in 2 different sites: FGT80F in site1, and FGT40F in site2
I had created a P2P IPsec VPN between both Fortigates some time ago (Connected through Internet)
This VPN was working fine for more than 2 years until now.
Recently I realliced that although the VPN was up, I couldnt access to anything in the other site through the VPN.
Both Fortigates have Firmware 7.6.4
In "Dashboard -> Network -> IPsec", I used the "Bring down -> Entire tunnel" option to "restart" the VPN.
After few seconds, the VPN was up again, and started to work (I started to reach anything in the other site through the VPN)
After some time (less than 2 hours, IDK how much time exactly), happened the same issue and I "solved" this again by "restarting" again the IPsec VPN, using the "Bring down -> Entire tunnel" option.
I cant see any related log.
Do you have any suggestion to try to diagnose why did this happen?
We didnt change anything recently.
Thanks in advance.
Regards,
Damián
Solved! Go to Solution.
Hi ,
Check if your ipsec phase2 selector is also up when the traffic goes down.
If this is the case you can enable auto-negotiate on phase2 configuration
Hi ,
Check if your ipsec phase2 selector is also up when the traffic goes down.
If this is the case you can enable auto-negotiate on phase2 configuration
Thank you stmz!!!
It seems that only twice happened, because since the second time I restarted the VPN, this is still working.
I will try this if this happen again!
Regards,
Damián
Hello team!!
The issue happened again today.
The following commands in the article did not show any output nor bring this up.
execute vpn ipsec tunnel up <Phase2 name>
diag vpn tunnel up <phase2 name>
When I used the "Bring down -> Phase2 selector", the VPN started to pass traffic again.
auto-negotiate option is not available on phase2-interface, but there is an option in the gui.
(IPsec-DialUp) # show full-configuration
config vpn ipsec phase2-interface
edit "IPsec-DialUp"
set phase1name "IPsec-DialUp"
set proposal aes128-sha1 aes256-sha1 aes128-sha256 aes256-sha256 aes128gcm aes256gcm chacha20poly1305
set pfs enable
set dhgrp 14 5
set replay enable
set keepalive disable
set add-route phase1
set inbound-dscp-copy phase1
set auto-discovery-sender phase1
set auto-discovery-forwarder phase1
set keylife-type seconds
set single-source disable
set route-overlap use-new
set encapsulation tunnel-mode
set comments "VPN: IPsec-DialUp (Created by VPN wizard)"
set diffserv disable
set protocol 0
set src-addr-type subnet
set src-port 0
set dst-addr-type subnet
set dst-port 0
set keylifeseconds 43200
set src-subnet 0.0.0.0 0.0.0.0
set dst-subnet 0.0.0.0 0.0.0.0
next
end
Thanks
Regards,
Damián
| User | Count |
|---|---|
| 2872 | |
| 1446 | |
| 840 | |
| 821 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.